heyeddi-pr-respond
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow is coherent for PR response automation, but it is high-risk because it enables autonomous code changes, commits, pushes, and public replies without confirmation, and it depends on several unverifiable helper commands whose provenance is not documented in the skill. Data flow to GitHub is proportionate, so this is not confirmed malware, but the execution trust and autonomy footprint are too broad to treat as benign.
Confidence: 87%Severity: 78%
Audit Metadata